Commit Graph

263 Commits

Author SHA1 Message Date
P4T12ICK a4ef2443cd appinspect failing fixes 2025-10-17 07:49:47 +02:00
Michael Haag a548ed769a Hellcat United (#3723)
* Hellcat United

* fixes

* 🍱

* 1 mas

* Update powershell_4104_hunting.yml
2025-10-16 16:53:02 -07:00
Michael Haag 64ed5bb1e8 APT 37 and The No Good Rustonotto (#3686)
* APT 37 and The No Good Rustonotto

## Updated analytics
```
detections/application/detect_html_help_spawn_child_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/bitsadmin_download_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cobalt_strike_named_pipes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_rundll32_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/executables_or_script_creation_in_temp_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/icedid_exfiltrated_archived_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/lolbas_with_network_traffic.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_4104_hunting.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/processes_tapping_keyboard_events.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/registry_keys_used_for_persistence.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_curl_network_connection.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_image_creation_in_appdata_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_mshta_spawn.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_process_executed_from_container_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_scheduled_task_from_public_directory.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_alternate_datastream___base64_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_rar.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archived_collected_data_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_cab_file_on_disk.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_curl_download_to_suspicious_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_invoke_restmethod.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_powershell_uploadstring.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_file_download_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_high_file_deletion_frequency.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_http_network_communication_from_msiexec.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_indicator_removal_via_rmdir.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_input_capture_using_credential_ui_dll.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_iso_lnk_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_obfuscated_files_or_information_via_rar_sfx.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_child_process_for_download.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_uncommon_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_executed_from_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_execution_from_programdata.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_commonly_abused_processes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_notepad.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_replication_through_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_command.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_name.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_service_created_with_suspicious_service_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_suspicious_driver_loaded_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_usbstor_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_wpdbusenum_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/winevent_scheduled_task_created_within_public_path.yml — APT37 Rustonotto and FadeStealer
detections/web/multiple_archive_files_http_post_traffic.yml — APT37 Rustonotto and FadeStealer
detections/web/plain_http_post_exfiltrated_data.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_expand_cabinet_file_extraction.yml — APT37 Rustonotto and FadeStealer
```

## New Story

```
stories/apt37_rustonotto_and_fadestealer.yml — APT37 Rustonotto and FadeStealer
```

* Create windows_expand_cabinet_file_extraction.yml

* Apply suggestion from @nasbench

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>

* updating conflicts

---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2025-10-13 13:54:03 -07:00
Michael Haag b6083e5076 GhostRedirectors 2025-09-18 13:39:40 -06:00
Teoderick Contreras 96786372a3 interlock_ransomware 2025-07-28 11:58:45 +02:00
Michael Haag 4e3598c522 Update windows_sharepoint_toolpane_endpoint_exploitation_attempt.yml 2025-07-21 13:11:43 -06:00
Michael Haag c5838d60da Create windows_sharepoint_spinstall0_get_request.yml 2025-07-21 09:28:05 -06:00
Michael Haag 13b49f5456 Sharing is Caring: A story of CVE-2025-53770 2025-07-20 17:03:37 -06:00
Nasreddine Bencherchali 523e5f4b94 add ftd equivalent analytic 2025-07-17 20:43:29 +02:00
Nasreddine Bencherchali 483e79feae Update citrix_adc_and_gateway_citrixbleed_2_memory_disclosure.yml
update formatting
2025-07-17 14:56:14 +02:00
Michael Haag c6af7c5b52 Update citrix_adc_and_gateway_citrixbleed_2_memory_disclosure.yml 2025-07-09 11:49:23 -06:00
Michael Haag b74094eb74 CitrixBleed2 2025-07-02 10:33:13 -06:00
ljstella 397107f88a Updated docs links in detections 2025-06-24 11:27:59 -05:00
Eric d9960562b8 Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different. 2025-05-02 14:10:46 -07:00
Michael Haag 074d13f001 BasketNetWeaving with Haag: No Shell Left Behind! 2025-04-28 10:33:17 -06:00
Bhavin Patel bb2045cce0 Merge branch 'develop' into crushingit 2025-04-18 12:45:18 -07:00
Michael Haag 9f8f28c0b5 Update crushftp_max_simultaneous_users_from_ip.yml 2025-04-18 13:27:09 -06:00
Michael Haag 95049154e9 Update crushftp_authentication_bypass_exploitation.yml 2025-04-18 13:25:39 -06:00
Bhavin Patel 8e6d4c69bf Merge branch 'develop' into remove_v5.4.0 2025-04-17 12:00:27 -07:00
Michael Haag 657ffbc9e4 Ground Control to Major Haag: Earth Alux
This PR adds a new analytic story for the Earth Alux threat actor, a sophisticated espionage group targeting government, technology, and telecommunications sectors in APAC and Latin America.
2025-04-16 21:55:12 -06:00
Bhavin Patel 5b7cfdb7d3 updating versions 2025-04-16 16:45:16 -07:00
Michael Haag fc81c76727 Haag's Crushed Shell: A Tale of CrushFTP Exploitation
CVE-2025-31161
2025-04-14 12:39:07 -06:00
Bhavin Patel 00253f3c6e Merge branch 'develop' into output_normalization_endpoint 2025-04-01 14:45:19 -07:00
Bhavin Patel 7168e32ea6 Merge branch 'develop' into sunnyside 2025-04-01 14:05:53 -07:00
Michael Haag 55b5bc77d2 fixagai 2025-04-01 14:48:54 -06:00
Michael Haag f435240b83 fixes 2025-04-01 14:34:18 -06:00
Patrick Bareiss 7541027f8e Merge branch 'develop' into output_normalization_endpoint 2025-04-01 09:41:58 +02:00
Michael Haag 20cb4400dc Haag Story 3: Attack Analytics to the Rescue
"There's a snake in my Tomcat!"

When malicious serialized objects started showing up at Sunnyside Server Farm, Security Sheriff Haag rounded up a posse of new detections to keep the web applications safe.

This PR delivers:
- Two new best friends: tomcat_session_file_upload_attempt and tomcat_session_deserialization_attempt
- A brand new playset: "Apache Tomcat Session Deserialization Attacks" analytic story
- No more crying when the bad toys try to upload .session files
- The claw of justice comes down when suspicious JSESSIONID cookies appear

Remember what Security Ranger Haag always says: "To HTTP response codes and beyond!"
2025-03-25 14:08:02 -06:00
Michael Haag ec5cf468e3 The Haag Identity: Operation Seashell Blizzard 🌊❄️
This PR introduces comprehensive updates to our detection analytics, focusing on tagging relevant detections with the new "Seashell Blizzard" analytic story. The changes include:
Version and date updates across 20 detection files, with dates standardized to '2025-03-24' or '2025-03-25', and version numbers incremented appropriately.
Analytics tagged with "Seashell Blizzard" include:
ConnectWise ScreenConnect vulnerability detections (authentication bypass, path traversal)
Exchange Server exploitation detections (ProxyShell, ProxyNotShell, web shell)
Credential access monitoring (LSASS dumps via TaskMgr and ProcDump)
Remote access software usage detections (file, process, registry)
Scheduled task abuse detections
SQL Server xp_cmdshell configuration changes
Registry hive dumping detection
Key updates:
- Added "Seashell Blizzard" tag to 20 existing detections

These changes enhance our ability to track and detect activities associated with the Seashell Blizzard threat actor.
2025-03-24 14:18:40 -06:00
Patrick Bareiss 1c9debe9a6 update versions 2025-03-14 13:47:44 +01:00
Patrick Bareiss 67dff5120a Merge branch 'develop' into output_normalization_endpoint 2025-03-13 09:22:06 +01:00
pyth0n1c d77736f7e4 Update detect_web_access_to_decommissioned_s3_bucket.yml
fix tests key again
2025-02-20 14:57:35 -08:00
Jose Hernandez 36f3b6eb35 shipping as experimental 2025-02-20 17:11:38 -05:00
Jose Hernandez 441ba47f3d fixing merge conflicts 2025-02-20 17:06:33 -05:00
pyth0n1c fde93c6d32 convert csv lookup to kvstore lookup.
Update references in description files
as well.
2025-02-19 14:50:53 -08:00
research-bot ddf3ed0797 adding baseline key to test 2025-02-18 08:49:59 -08:00
research-bot 43c999440c updating yamls 2025-02-18 08:42:18 -08:00
research-bot 2d54affae2 updating dummy dataset links 2025-02-13 17:30:11 -08:00
research-bot 0ec052b8f9 updating yaml to pass build and adding lookup, minor fixes 2025-02-13 15:36:01 -08:00
Jose Hernandez d83efc4dd1 adding datasets 2025-02-13 16:58:01 -05:00
Jose Enrique Hernandez fda0c88916 Merge branch 'develop' into 8_million_requests 2025-02-13 16:42:17 -05:00
Jose Hernandez 172e1d5db5 first draft 2025-02-12 18:03:06 -05:00
pyth0n1c 45599e0b18 Clean up MITRE Tagging. When a type is defined, such as T1003, DO NOT allow a subtype such as T1003.001 to be defined. Remove the generic type T1003 and keep the subtype T1003.001. However, it is acceptable for a subtype to be defined or for a type to be defined separately. It is also okay for multiple subtypes to be defined. 2025-02-10 12:28:22 -08:00
Steven Dick 41c92476b9 Update detect_remote_access_software_usage_url.yml 2025-02-06 08:04:38 -05:00
Steven Dick 7773664924 Update detect_remote_access_software_usage_url.yml 2025-02-06 07:57:46 -05:00
research-bot 76a9a02c9e updating versions 2025-02-05 10:49:03 -08:00
research-bot 6c3e7df1ad notable to finding 2 2025-01-24 17:03:47 -08:00
Nasreddine Bencherchali c0418cff2e Merge branch 'develop' of https://github.com/splunk/security_content into major-updates 2025-01-22 11:40:26 +01:00
Michael Haag 8ce3783394 Update windows_exchange_autodiscover_ssrf_abuse.yml
- Updated detection description to better explain ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) attack patterns
- Enhanced search query:
  - X-Rps-CAT parameter
  - Suspicious user agent strings
2025-01-16 10:02:05 -07:00
pyth0n1c fdaa038eab Finish removing extra fields, or renaming
misnamed fields, in endpoint detections
2025-01-03 15:47:32 -08:00